1 { config, lib, pkgs, ... }:
6 cfg = config.services.myPhpfpm;
7 enabled = cfg.poolConfigs != {} || cfg.pools != {};
9 stateDir = "/run/phpfpm";
11 poolConfigs = cfg.poolConfigs // mapAttrs mkPool cfg.pools;
18 fpmCfgFile = pool: poolConfig: pkgs.writeText "phpfpm-${pool}.conf" ''
28 phpIni = poolPhpOptions: (pkgs.runCommand "php.ini" {
29 inherit (cfg) phpPackage phpOptions;
30 inherit poolPhpOptions;
32 sendmail_path = "/run/wrappers/bin/sendmail -t -i"
34 passAsFile = [ "nixDefaults" "phpOptions" "poolPhpOptions" ];
36 cat $phpPackage/etc/php.ini $nixDefaultsPath $phpOptionsPath $poolPhpOptionsPath > $out
43 extraConfig = mkOption {
47 Extra configuration that should be put in the global section of
48 the PHP-FPM configuration file. Do not specify the options
49 <literal>error_log</literal> or
50 <literal>daemonize</literal> here, since they are generated by
55 phpPackage = mkOption {
58 defaultText = "pkgs.php";
60 The PHP package to use for running the PHP-FPM service.
64 phpOptions = mkOption {
72 "Options appended to the PHP configuration file <filename>php.ini</filename>.";
75 poolPhpConfigs = mkOption {
77 type = types.attrsOf types.lines;
78 example = literalExample ''
80 extension = some_extension.so
85 Extra lines that go into the php configuration specific to pool.
89 poolConfigs = mkOption {
91 type = types.attrsOf types.lines;
92 example = literalExample ''
94 listen = /run/phpfpm/mypool
99 pm.min_spare_servers = 5
100 pm.max_spare_servers = 20
101 pm.max_requests = 500
106 A mapping between PHP-FPM pool names and their configurations.
107 See the documentation on <literal>php-fpm.conf</literal> for
108 details on configuration directives. If no pools are defined,
109 the phpfpm service is disabled.
114 type = types.attrsOf (types.submodule (import ./pool-options.nix {
118 example = literalExample ''
121 listen = "/path/to/unix/socket";
126 pm.start_servers = 10
127 pm.min_spare_servers = 5
128 pm.max_spare_servers = 20
129 pm.max_requests = 500
134 PHP-FPM pools. If no pools or poolConfigs are defined, the PHP-FPM
141 config = mkIf enabled {
143 systemd.slices.phpfpm = {
144 description = "PHP FastCGI Process manager pools slice";
147 systemd.targets.phpfpm = {
148 description = "PHP FastCGI Process manager pools target";
149 wantedBy = [ "multi-user.target" ];
152 systemd.services = flip mapAttrs' poolConfigs (pool: poolConfig:
153 nameValuePair "phpfpm-${pool}" {
154 description = "PHP FastCGI Process Manager service for pool ${pool}";
155 after = [ "network.target" ];
156 wantedBy = [ "phpfpm.target" ];
157 partOf = [ "phpfpm.target" ];
162 cfgFile = fpmCfgFile pool poolConfig;
163 poolPhpIni = cfg.poolPhpConfigs.${pool} or "";
165 Slice = "phpfpm.slice";
166 PrivateDevices = true;
167 ProtectSystem = "full";
169 # XXX: We need AF_NETLINK to make the sendmail SUID binary from postfix work
170 RestrictAddressFamilies = "AF_UNIX AF_INET AF_INET6 AF_NETLINK";
172 ExecStart = "${cfg.phpPackage}/bin/php-fpm -y ${cfgFile} -c ${phpIni poolPhpIni}";
173 ExecReload = "${pkgs.coreutils}/bin/kill -USR2 $MAINPID";